CVE-2022-2057
Summary
| CVE | CVE-2022-2057 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-30 16:15:00 UTC |
| Updated | 2023-11-07 03:46:00 UTC |
| Description | Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| tiffcrop: FPE in computeOutputPixelOffsets, tiffcrop.c:5936 (Different from #347) (#427) · Issues · libtiff / libtiff · GitLab |
MISC |
gitlab.com |
|
| [SECURITY] Fedora 35 Update: libtiff-4.4.0-2.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| fix the FPE in tiffcrop (#415, #427, and #428) (!346) · Merge requests · libtiff / libtiff · GitLab |
MISC |
gitlab.com |
|
| Debian -- Security Information -- DSA-5333-1 tiff |
DEBIAN |
www.debian.org |
|
| [SECURITY] Fedora 36 Update: libtiff-4.4.0-2.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| 2022/CVE-2022-2057.json · master · GitLab.org / cves · GitLab |
CONFIRM |
gitlab.com |
|
| [SECURITY] Fedora 36 Update: libtiff-4.4.0-2.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| June 2022 LibTIFF Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [SECURITY] Fedora 35 Update: libtiff-4.4.0-2.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] [DLA 3278-1] tiff security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Legacy QID Mappings
- 160390 Oracle Enterprise Linux Security Update for libtiff (ELSA-2023-0095)
- 160411 Oracle Enterprise Linux Security Update for libtiff (ELSA-2023-0302)
- 181488 Debian Security Update for tiff (DLA 3278-1)
- 181520 Debian Security Update for tiff (DSA 5333-1)
- 182583 Debian Security Update for tiff (CVE-2022-2057)
- 198944 Ubuntu Security Notification for LibTIFF Vulnerabilities (USN-5619-1)
- 241054 Red Hat Update for libtiff (RHSA-2023:0095)
- 241120 Red Hat Update for libtiff (RHSA-2023:0302)
- 282943 Fedora Security Update for libtiff (FEDORA-2022-edf7301147)
- 282959 Fedora Security Update for libtiff (FEDORA-2022-b9c2a3a2b7)
- 354326 Amazon Linux Security Advisory for libtiff : ALAS2022-2022-194
- 354588 Amazon Linux Security Advisory for libtiff : ALAS-2022-194
- 355159 Amazon Linux Security Advisory for libtiff : ALAS2023-2023-050
- 502794 Alpine Linux Security Update for tiff
- 503030 Alpine Linux Security Update for tiff
- 503131 Alpine Linux Security Update for tiff
- 505944 Alpine Linux Security Update for tiff
- 672155 EulerOS Security Update for libtiff (EulerOS-SA-2022-2443)
- 672204 EulerOS Security Update for libtiff (EulerOS-SA-2022-2469)
- 672462 EulerOS Security Update for libtiff (EulerOS-SA-2022-2850)
- 672464 EulerOS Security Update for libtiff (EulerOS-SA-2022-2825)
- 672478 EulerOS Security Update for libtiff (EulerOS-SA-2023-1039)
- 672508 EulerOS Security Update for libtiff (EulerOS-SA-2023-1014)
- 672526 EulerOS Security Update for libtiff (EulerOS-SA-2023-1128)
- 672539 EulerOS Security Update for libtiff (EulerOS-SA-2023-1104)
- 752422 SUSE Enterprise Linux Security Update for tiff (SUSE-SU-2022:2647-1)
- 752430 SUSE Enterprise Linux Security Update for tiff (SUSE-SU-2022:2648-1)
- 902422 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (10026)
- 902430 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (10008)
- 904804 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (10026-1)
- 905950 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (10026-2)
- 906338 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (10008-2)
- 940871 AlmaLinux Security Update for libtiff (ALSA-2023:0095)
- 940898 AlmaLinux Security Update for libtiff (ALSA-2023:0302)
- 960525 Rocky Linux Security Update for libtiff (RLSA-2023:0302)
- 960537 Rocky Linux Security Update for libtiff (RLSA-2023:0095)